๐Ÿ” CVE Alert

CVE-2026-56239

HIGH 7.6

Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which performs sensitive billing operations without enforcing internal authorization checks (no validation of auth.uid(), org membership, or check_min_rights). Because the function runs with the owner's privileges, it bypasses Row Level Security. If EXECUTE permission is available to the authenticated or anon roles (explicitly or via default privileges), an authenticated user could invoke it via Supabase RPC to manipulate billing data for arbitrary organizations, including unauthorized credit depletion and fraudulent overage event insertion.

CWE CWE-269
Vendor capgo
Product capgo
Published Jun 21, 2026
Stay Ahead of the Next One

Get instant alerts for capgo capgo

Be the first to know when new high vulnerabilities affecting capgo capgo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low

Affected Versions

Capgo / Capgo
0 < 12.128.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Cap-go/capgo/security/advisories/GHSA-qq85-vjrq-m75g vulncheck.com: https://www.vulncheck.com/advisories/capgo-privilege-escalation-via-security-definer-function-apply-usage-overage

Credits

๐Ÿ” hunt-with-4bh1